Malicious PDF — malware analysis report

Static analysis result for SHA-256 26361931981509c0…

MALICIOUS

PDF

46.8 KB Authoring application: Soda PDF
MD5: 284299318ace1319b788176bcc02d9c1 SHA-1: 03d105638309c0e3fbf7552e225f1e3a7f6f7666 SHA-256: 26361931981509c00ebd1d6c4998a1b2f8dc4fbc6466c627127231f969256303
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF document that contains embedded links pointing to other PDF files. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or malware distribution. The embedded links are the primary indicators of compromise, suggesting a lure to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://binkaudenaarde.weebly.com/uploads/1/3/0/5/130590550/gasotafufedax.pdf
    • http://ohayocleaning.com/uploads/1/3/0/6/130620919/rujitogevepiwaw-pezexu-ropuje.pdf
    • http://soundfulsoul.org/uploads/1/3/0/6/130604630/luserijo-lorepijedituxe.pdf
    • http://benkregel.com/uploads/1/3/0/3/130323471/130323471.html#figuras+retoricas+basicas

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001051.bin
fd5a1d868517b548db4f341a7e162f9ee588ec5f808d8c9cd8a99e9b58a42a02
pdf-font-stream PDF embedded font (sfnt) at offset 0x1051 9192 bytes
font_01_sfnt_off00006fd4.bin
c7143368894299a997ed09f05024df052d964886bc902d598de4a6791c50751f
pdf-font-stream PDF embedded font (sfnt) at offset 0x6FD4 10292 bytes